request.url.query is empty when Host header is ended with # #1557
Unanswered
bbangjooo
asked this question in
Potential Issue
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
Hello,
I found that
request.urlis made fromHostheader(URL class).So when I send
Hostheader ended with#,request.url.queryis empty butrequest.query_paramsstill contains query strings. This behavior is also occured betweenrequest.url.pathandrequest.path_paramsexample :
Hostheader ended with#I think the example is not intended behavior.
Expected impact
If server owner sanitize or filter their incoming request using
request.url.queryorrequest.url.pathfor any reason, It will be bypassed by sending request withHostheader ended with#Beta Was this translation helpful? Give feedback.
All reactions